Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown
CVE-2004-2330
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
ColdFusion MX 6.1 and 6.1 J2EE allows remote attackers to cause a denial of service via an HTTP request containing a large number of form fields.
0
Attacker Value
Unknown
CVE-2004-1478
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session.
0
Attacker Value
Unknown
CVE-2004-2331
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.
0
Attacker Value
Unknown
CVE-2004-2204
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administrative passwords by creating CFML scripts that use CreateObject or CFOBJECT.
0
Attacker Value
Unknown
CVE-2004-0646
Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.
0
Attacker Value
Unknown
CVE-2004-0928
Disclosure Date: October 05, 2004 (last updated February 22, 2025)
The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in ";.cfm".
0
Attacker Value
Unknown
CVE-2004-0407
Disclosure Date: June 01, 2004 (last updated February 22, 2025)
The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.
0
Attacker Value
Unknown
CVE-2004-1815
Disclosure Date: March 15, 2004 (last updated February 22, 2025)
Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).
0